216.73.216.226

CloudSorcerer – A new APT targeting Russian government entities

· Published 08/07/2024 19:18 · Modified 08/07/2024 19:55

Export JSON

Essential information

Published
08/07/2024 19:18
Modified
08/07/2024 19:55
Tags
2024-07-08 c programming language cloudsorcerer github microsoft com object ror14 algorithm
Related entities
1 observables, 1 intrusion sets (apt), 8 techniques (mitre), 1 malware, 2 others

Description

In May 2024, Kaspersky discovered a sophisticated cyberespionage tool called , targeting Russian government entities. This malware leverages cloud resources like Microsoft Graph, Yandex Cloud, and Dropbox as command-and-control (C2) servers, accessing them through APIs using authentication tokens. It also utilizes as its initial C2 server. employs inter-process communication through Windows pipes and adapts its behavior based on the running process, showcasing its advanced nature. While reminiscent of the CloudWizard APT, the code differs significantly, suggesting is likely a new actor inspired by similar techniques.

External references